Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
79.107 exploits
GitHub PoC1
CVE-2020-5902
CVE-2020-5902CRITICALsob ataqueransomware06 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
GitHub PoC70
Proof of concept for CVE-2020-5902
CVE-2020-5902CRITICALsob ataqueransomware05 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
GitHub PoC374
CVE-2020-5902 BIG-IP
CVE-2020-5902CRITICALsob ataqueransomware05 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
Exploit-DB
BIG-IP 15.0.0 < 15.1.0.3 / 14.1.0 < 14.1.2.5 / 13.1.0 < 13.1.3.3 / 12.1.0 < 12.1.5.1 / 11.6.1 < 11.6.5.1 - Traffic Management User Interface 'TMUI' Remote Code Execution (PoC)
CVE-2020-5902CRITICALsob ataqueransomwarewebappslinux05 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
GitHub PoC55
Automated script for F5 BIG-IP scanner (CVE-2020-5902) using hosts retrieved from Shodan API.
CVE-2020-5902CRITICALsob ataqueransomware05 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
GitHub PoC12
POC code for checking for this vulnerability. Since the code has been released, I decided to release this one as well. Patch Immediately!
CVE-2020-5902CRITICALsob ataqueransomware05 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
GitHub PoC8
rwincey/CVE-2020-5902-NSE
CVE-2020-5902CRITICALsob ataqueransomware05 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
GitHub PoC8
nsflabs/CVE-2020-5902
CVE-2020-5902CRITICALsob ataqueransomware05 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-5902CRITICALsob ataqueransomware05 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2020-5902CRITICALsob ataqueransomware05 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2020-5902CRITICALsob ataqueransomware05 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-5902CRITICALsob ataqueransomware05 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-5902CRITICALsob ataqueransomware05 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-5902CRITICALsob ataqueransomware05 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
GitHub PoC
Simple OpenSSL TLS Heartbeat (CVE-2014-0160) Scanner and Exploit (Multiple SSL/TLS versions)
CVE-2014-0160HIGHsob ataque04 jul 2020
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC9
CVE-2020-5902
CVE-2020-5902CRITICALsob ataqueransomware04 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
GitHub PoC
Kenun99/CVE-2019-16113-Dockerfile
CVE-2019-1611303 jul 2020
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RISCO
abrir
GitHub PoC17
The official exploit for OCS Inventory NG v2.7 Remote Command Execution CVE-2020-14947
CVE-2020-1494702 jul 2020
OCS Inventory NG 2.7 allows Remote Command Execution via shell metacharacters to require/commandLine/CommandLine.php bec
28RISCO
abrir
Exploit-DB
OCS Inventory NG 2.7 - Remote Code Execution
CVE-2020-14947webappsmultiple02 jul 2020
OCS Inventory NG 2.7 allows Remote Command Execution via shell metacharacters to require/commandLine/CommandLine.php bec
28RISCO
abrir
GitHub PoC2
reversebrain/CVE-2019-18988
CVE-2019-18988HIGHsob ataque01 jul 2020
TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for dif
86RISCO
abrir
VulnCheck XDB
local
CVE-2019-18988HIGHsob ataque01 jul 2020
TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for dif
86RISCO
abrir
Metasploit200
F5 BIG-IP TMUI Directory Traversal and File Upload RCE
CVE-2020-5902CRITICALsob ataqueransomware30 jun 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
GitHub PoC1
Webmin < 1.290 / Usermin < 1.220 - Arbitrary File Disclosure (Python3)
CVE-2006-339230 jun 2020
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RISCO
abrir
VulnCheck XDB
local
CVE-2020-0787HIGHsob ataqueransomware30 jun 2020
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-2883CRITICALsob ataque30 jun 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISCO
abrir
Metasploit600
openSIS Unauthenticated PHP Code Execution
CVE-2020-1338330 jun 2020
openSIS through 7.4 allows Directory Traversal.
30RISCO
abrir
Metasploit600
openSIS Unauthenticated PHP Code Execution
CVE-2020-1338130 jun 2020
openSIS through 7.4 allows SQL Injection.
30RISCO
abrir
Metasploit600
openSIS Unauthenticated PHP Code Execution
CVE-2020-1338230 jun 2020
openSIS through 7.4 has Incorrect Access Control.
30RISCO
abrir
GitHub PoC19
CVE-2013-2028 python exploit
CVE-2013-202827 jun 2020
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cau
60RISCO
abrir
GitHub PoC
cyberharsh/Shellbash-CVE-2014-6271
CVE-2014-6271CRITICALsob ataque26 jun 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
anteriorpágina 764 / 2.637próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.